6.2

CVE-2024-50929

Exploit

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).

Data is provided by the National Vulnerability Database (NVD)
SilabsZ-wave Software Development Kit Version <= 7.21.1
   SilabsEfr32zg14p231f256gm32 Version-
   SilabsEfr32zg23a010f512gm40 Version-
   SilabsEfr32zg23a010f512gm48 Version-
   SilabsEfr32zg23a020f512gm40 Version-
   SilabsEfr32zg23a020f512gm48 Version-
   SilabsEfr32zg23b010f512im40 Version-
   SilabsEfr32zg23b010f512im48 Version-
   SilabsEfr32zg23b011f512im40 Version-
   SilabsEfr32zg23b020f512im40 Version-
   SilabsEfr32zg23b020f512im48 Version-
   SilabsEfr32zg23b021f512im40 Version-
   SilabsZgm130s037hgn Version-
   SilabsZgm230sa27hgn Version-
   SilabsZgm230sb27hgn Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-281 Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.